Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Admin Console
    Administration
    Managing Administrators for RBAC V3
    Policies RBAC V3

    Policies RBAC V3

    RBAC V3 is an overarching framework that governs what an admin can do in the Netskope platform. It does not matter whether the admin is doing it via the UI or REST API.

    Product capabilities are divided up into abstract functions. Every admin who logs in is assigned a role. And it is that role that defines, for each and every function, the permission the admin has:

    • None – this role has no access to this function
    • View – this role has read access to this function and can see but not change configuration or data under this function’s jurisdiction.
    • Manage – this role has both read and write access to this function and can change configuration or data under this function’s jurisdiction
    • Manage & Apply – this role has both read and write access to this function and can change configuration or data under this function’s jurisdiction. In addition, this role can make and apply changes immediately.

    Policy Flavors

    Some policy sets have multiple use cases rolled up into one, those use cases breaks up the policy into different functions because admins may want more specific control over which admins (roles) can manage which kind of policies.

    For example:

    • You only want your data compliance security team to create and define DLP policies, for both real-time and API-enabled protection.
    • You only want your network security team to create firewall policies.

    Real-time Protection Policy

    • RTP Policy is broken up into various functions based on the traffic, like flavors of ice cream.
    • DLP and Threat functions are additive functions, like toppings on the ice cream.

    RTP Policy Flavors and Topping Definitions

    FLAVOR OR TOPPINGFUNCTIONDESCRIPTION
    Ice cream FLAVORCloud Apps PolicyDestination traffic is set to cloud apps or app instance.
    Ice cream flavorWeb PolicyDestination traffic is set to categories.
    Ice cream flavorFirewall PolicyDestination traffic is set to at least one non-web app.
    Ice cream flavorMail Relay PolicyDestination traffic is set to SMTP.
    Ice cream flavorNPA PolicyDestination traffic is set to private apps.
    Ice cream flavorDNS PolicyDestination traffic is set to DNS.
    Ice cream TOPPINGDLP PolicyHas a DLP profile specified.
    Ice cream toppingThreat Protection PolicyHas a TSS profile specified.
    Ice cream toppingBrowser Isolation PolicyAction is set to “Isolate.”

    API Data Protection Policy

    • API policy has a single contextual policy function, like only one flavor of ice cream.
    • DLP and Threat functions are additive functions, like toppings on the ice cream.

    API Policy Flavors and Topping Definitions

    FLAVOR OR TOPPINGFUNCTIONDESCRIPTION
    Ice cream FLAVORPolicyAny API Data Protection Policy
    Ice cream TOPPINGDLP PolicyHas a DLP profile specified
    Ice cream toppingThreat Protection PolicyHas a TSS profile specified
    Viewing Policies

    The permission (None, View, Manage, Manage And Apply) works in conjunction with the policy flavors. This allows admins to control, very precisely, which admin users can manage which policies.

    PERMISSIONDESCRIPTION
    Viewing and Managing PoliciesEven if policies of different flavors show up in the same table, the rules described above still applies.

    Example 1: Admin use has “none” access to Mail Relay, NPA, and DNS Policy. They cannot not see these policies in the RTP policy table. Only the policies they have a minimum of “view” permission to show up in the table are visible to them.

    Example 2: Admin has “manage” permission to Cloud App Policy but only “view” permission to the other flavors. This means that despite being able to see all of the policies in the table, the admin user can only edit the ones meant for cloud app traffic.
    Viewing Pending ChangesThe pending changes an admin user can see is consistent with those that they have a minimum of “view” permission. This means, if admin user A has “none” access to DLP Policy, admin user A cannot see DLP policies in pending changes.

    Note, even if the admin user can view the pending changes, it doesn’t mean they can apply. This means, that an admin who has “manage” permission but not “apply” permission may submit approval to an admin who does.
    Applying ChangesThe pending changes an admin user can apply should be consistent with what they have “apply” permission on. This means, if there are more pending changes than what the admin user can apply, the admin user should be able to apply just the subset of pending changes they have access to.

    RBAC V3 Function Mapping

    Product capabilities are divided into abstract functions. Every admin who logs in is assigned a role. And it is that role that defines, for each and every function, the permission the admin has:

    Manage And Apply – this role has both read and write access to this function and can change configuration or data under this function’s jurisdiction. In addition, this role can make and apply changes immediately.

    None – this role has no access to this function

    View – this role has read access to this function and can see but not change configuration or data under this function’s jurisdiction.

    Manage – this role has both read and write access to this function and can change configuration or data under this function’s jurisdiction

    The following table is broken up by Function 1 and Function 2, product capabilities. Function 1’s permission depends on at least one or all of Function 2’s permission being set to a minimum permission.

    In other words, you can’t set Function 1’s permission to R or R+W unless at least one or all of Function 2’s permission is set to a minimum permission or higher. Otherwise, Function 1 will not work correctly.

    FUNCTIONAL AREAFUNCTION 1F1 PERMISSIONDEPENDS ON FUNCTION 2F2 MINIMUM PERMISSION
    Real-time ProtectionDLP PolicyR+WAt least one-Cloud Apps Policy
    -Web Policy
    -Firewall Policy
    R+W
    Real-time ProtectionThreat Protection PolicyR+WAt least one-Cloud Apps Policy
    -Web Policy
    -Firewall Policy
    R+W
    Real-time ProtectionBrowser Isolation PolicyR+WN/AWeb policyR+W
    Real-time ProtectionDNS PolicyR+WAt least one-Web Policy
    -Firewall Policy
    R+W
    Real-time ProtectionDLP PolicyRAt least one-Cloud Apps Policy
    -Web Policy
    -Firewall Policy
    R
    Real-time ProtectionThreat Protection PolicyRAt least one-Cloud Apps Policy
    -Web Policy
    -Firewall Policy
    R
    Real-time ProtectionBrowser Isolation PolicyRN/AWeb PolicyR
    Real-time ProtectionDNS PolicyRAt least one-Web Policy
    -Firewall Policy
    R
    Real-time ProtectionCloud Apps PolicyR+WAll-Users and Groups
    -Custom Apps
    -App Instance
    -Network Location Profile
    -Constraint Profile
    -HTTP Header Profile
    -File Profile
    -Device Classification
    -User Notification Template
    -Email Notification Template
    R
    Real-time ProtectionWeb PolicyR+WAll-Users & Groups
    -Custom Category
    -URL List
    -Network Location
    -Constraint Profile
    -HTTP Header Profile
    -Device Classification
    -File Profile
    -User Notification Template
    -Email Notification Template
    -Forward to Proxy Integration
    R
    Real-time ProtectionFirewall PolicyR+WAll-Users & Groups
    -Service
    -Network Location Profile
    -User Notification Template
    -Email Notification Template
    R
    Real-time ProtectionMail Relay PolicyR+WAll-Users & Groups
    -DLP profile
    -Email Notification Template
    -Constraint Profile
    R
    Real-time ProtectionNPA PolicyR+WAll-Users & Groups
    -Private Apps
    -Device Classification
    -User Notification Template
    R
    Real-time ProtectionDNS PolicyR+WAll-Users & Groups
    -DNS Profile
    -Network Location Profile
    R
    Real-time ProtectionDLP PolicyR+WAll-DLP Profile
    -Quarantine Profile
    R
    Real-time ProtectionThreat Protection PolicyR+WAll-Threat Protection PolicyR
    Real-time ProtectionBrowser Isolation PolicyR+WAllRBI TemplateR
    Real-time ProtectionView All PoliciesRN/APolicy GroupR
    Real-time ProtectionCloud Apps PolicyRN/APolicy GroupR
    Real-time ProtectionWeb PolicyRN/APolicy GroupR
    Real-time ProtectionFirewall PolicyRN/APolicy GroupR
    Real-time ProtectionMail Relay PolicyRN/APolicy GroupR
    Real-time ProtectionNPA PolicyRN/APolicy GroupR
    Real-time ProtectionDNS PolicyRN/APolicy GroupR
    Real-time ProtectionDLP PolicyRN/APolicy GroupR
    Real-time ProtectionThreat Protection PolicyRN/APolicy GroupR
    Real-time ProtectionBrowser Isolation PolicyRN/APolicy GroupR
    Real-time ProtectionCloud Apps PolicyR+WN/APolicy GroupR
    Real-time ProtectionWeb PolicyR+WN/APolicy GroupR
    Real-time ProtectionFirewall PolicyR+WN/APolicy GroupR
    Real-time ProtectionMail Relay PolicyR+WN/APolicy GroupR
    Real-time ProtectionNPA PolicyR+WN/APolicy GroupR
    Real-time ProtectionDNS PolicyR+WN/APolicy GroupR
    Real-time ProtectionDLP PolicyR+WN/APolicy GroupR
    Real-time ProtectionThreat Protection PolicyR+WN/APolicy GroupR
    Real-time ProtectionBrowser Isolation PolicyR+WN/APolicy GroupR
    API Data ProtectionDLP PolicyR+WAll-DLP Profile
    -Quarantine Profile
    -Legal Hold Profile
    R
    API Data ProtectionDLP PolicyR+WN/APolicyR+W
    API Data ProtectionThreat Protection PolicyR+WAll-Threat Protection Profile
    -Quarantine Profile
    R
    API Data ProtectionThreat Protection PolicyR+WN/APolicyR+W
    API Data ProtectionDLP PolicyRN/APolicyR
    API Data ProtectionThreat Protection PolicyRN/APolicyR
    API Data ProtectionPolicyRAll-Users & Groups
    -User Profile
    -Domain Profile
    -CASB API
    R
    API Data ProtectionPolicyR+WAll-Users & Groups
    -User Profile
    -Domain Profile
    -CASB API
    -Sensitivity Label
    -Quarantine Profile
    -Legal Hold Profile
    -Email Notification Template
    R
    DLPLegal Hold FilesRAll-CASB API
    -Legal Hold Profile
    R
    DLPQuarantine FilesRAll-CASB API
    -Quarantine Profile
    R
    DLPLegal Hold FilesR+WAll-CASB API
    -Legal Hold Profile
    R
    DLPQuarantine FilesR+WAll-Quarantine ProfileR
    DLPQuarantine FilesR+WAll-CASB APIR+W

    RBAC V3 and Retro Scans

    Retro Scan contains policies. If a retro scan contains any DLP policy, Netskope considers it a DLP retro scan. This also applies to Threat Protection.

    The table below lists the retro scan action and the minimum permission required to run a retro scan for policies.

    If the minimum permission is not available, the UI will not display the button or ellipses to take action for a retro scan.
    Retro Scan ActionMinimum Permission
    Start ScanR+W
    Pause ScanR+W
    Cancel ScanR+W
    Edit ScanR+W
    Clone ScanR+W
    Delete ScanR+W
    View ScanR
    Edit PolicyR+W
    Clone PolicyR+W
    Delete PolicyR+W

    In this Topic
    • Policies RBAC V3